Business Wire

PCI Security Standards Council Publishes Security Requirements for Software-Based PIN Entry on COTS Devices

Share

Today the PCI Security Standards Council (PCI SSC) announced a new PCI Security Standard for software-based PIN entry on commercial off-the-shelf devices (COTS), such as smartphones and tablets. The PCI Software-Based PIN Entry on COTS (SPoC) Standard provides requirements for developing secure solutions that enable EMV contact and contactless transactions with PIN entry on the merchant’s consumer device using a secure PIN entry application in combination with a Secure Card Reader for PIN (SCRP).

“Mobile point-of-sale (MPOS) solutions have become very popular with smaller merchants for their flexibility and efficiency. MPOS has enabled them to take orders and accept payments on a tablet or smartphone, anytime and anywhere. However, some small merchants in markets that require EMV chip-and-PIN acceptance may have found the costs of investing in hardware prohibitive,” said Aite Group Senior Analyst Ron van Wezel. “With the new PIN entry standard, the PCI Council has responded to market need by specifying the security requirements for allowing PIN entry directly on the mobile touchscreen. This means that merchants can accept payments with just their mobile device and a small, cost efficient card reader connected to it along with a secure PIN entry application. The payment industry will benefit overall from the wider choice in payment acceptance, as it will drive the growth of electronic transactions.”

“The PCI Council has a long history of developing standards for protecting PIN as a verification method in hardware-based solutions. Existing PCI PIN Standards require hardware-based security protection of the PIN,” said PCI SSC Chief Technology Officer Troy Leach. “We are now building on this foundation with a new standard that allows for an alternative approach to secure PIN entry by isolating the PIN from other data and using a new robust set of security controls that extend beyond the physical hardware device itself. The PCI Software-Based PIN Entry Standard gives solution providers and application developers a baseline of security requirements specifically for accepting EMV contact and contactless transactions using software-based PIN entry.”

Key security principles included in the standard’s security and test requirements are:

  • Active monitoring of the service, to mitigate against potential threats to the payment environment within the phone or tablet;
  • Isolation of the PIN from other account data;
  • Ensuring the software security and integrity of the PIN entry application on the COTS device;
  • Protection of the PIN and account data using a PCI approved Secure Card Reader for PIN (SCRP).

The Software-Based PIN Entry on COTS Security Requirements are for solution providers to use in designing each part of a complete solution. These requirements are available now on the PCI SSC website.

The Software-Based PIN Entry on COTS Test Requirements outline testing processes for laboratories to use in evaluating solutions against the standard. These will be published in the next month, followed by a supporting program that will list PCI validated solutions on the PCI SSC website for merchant use.

For more information on the new standard, read PCI Perspectives blog post New PCI Software-Based PIN Entry on COTS Standard .

“This standard gives solution providers and application developers a baseline of security requirements for how to securely accept PIN-based transactions on a COTS device, as well as methods to test that security is working, even as updates to the devices and applications occur frequently. PCI validated solutions will meet a robust set of security objectives that have been tested by independent laboratories,” added Leach. “More and more businesses are now accepting payments with smartphones, tablets and other COTS devices, especially within the small business community. The PCI SSC Software-Based PIN Entry Solution listing will provide these merchants with a resource for selecting PIN entry solutions that have been evaluated and tested by payment security laboratories, and their customers will benefit by having the best available protection for their payment data.”

About the PCI Security Standards Council
The PCI Security Standards Council (PCI SSC) leads a global, cross-industry effort to increase payment security by providing industry-driven, flexible and effective data security standards and programs that help businesses detect, mitigate and prevent cyberattacks and breaches. Connect with the PCI SSC on LinkedIn. Join the conversation on Twitter @PCISSC. Subscribe to the PCI Perspectives Blog.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

Contact information

PCI Security Standards Council
Mark Meissner, +1-202-744-8557
press@pcisecuritystandards.org
Twitter @PCISSC

About Business Wire

For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

CCM Biosciences Announces Presentation of Data on its First-In-Class AML Drug Program at ASCO 202520.5.2025 23:30:00 EEST | Press release

CCM Biosciences, a diversified pharmaceutical discovery and development company, today announced the upcoming presentation of its next-generation FLT3 inhibitor drug program for acute myeloid leukemia (AML) at the 2025 Annual Conference of the American Society of Clinical Oncology (ASCO), taking place May 30 to June 3 in Chicago. Acute Myeloid Leukemia (AML) is the most severe form of leukemia with few treatment options, and a malignancy frequently driven by mutations in the FMS-like tyrosine kinase 3 (FLT3) gene. The FLT3 internal tandem duplication (ITD) and tyrosine kinase domain (TKD) mutations, particularly D835 and F691, appear in approximately 30% of AML patients, often leading to poor prognosis and resistance to existing therapies. Gilteritinib (Xospata®; Astellas Pharma, peak annual sales projection: $1.5 billion) and Quizartinib (Vanflyta®; Daiichi Sankyo) are two FDA-approved FLT3 inhibitors, with the former approved only for relapsed/refractory AML and the latter approved o

IonQ Partners with Sweden’s Einride to Develop Quantum Supply Chain and Quantum-Enhanced Logistics for Autonomous Driving Solutions20.5.2025 23:05:00 EEST | Press release

IonQ (NYSE: IONQ), a leading commercial quantum computing and networking company, today announced an investment partnership with Einride, a leading global freight mobility company that provides digital, electric, and autonomous technology to explore how quantum computing can drive the next generation of fleet optimization and logistics. Together, IonQ and Einride will develop quantum applications that address large-scale routing and scheduling problems that have traditionally challenged classical computing. By combining IonQ’s advanced quantum systems with Einride’s expertise in autonomous fleet logistics, the two companies will work to unlock new levels of efficiency, reliability, and sustainability for the global freight industry. “Einride shares our belief that quantum computing will fundamentally reshape and improve how large industries such as transportation and logistics operate,” said Niccolo de Masi, CEO of IonQ. “This partnership is aimed at creating a powerful platform with u

CCM Biosciences Announces Presentation of Data on its First-In-Class NSCLC Drug Program at ASCO 202520.5.2025 22:26:00 EEST | Press release

CCM Biosciences, a diversified pharmaceutical discovery and development company, today announced the upcoming presentation of its 4th-generation EGFR inhibitor drug program for non-small cell lung cancer (NSCLC) at the 2025 Annual Conference of the American Society of Clinical Oncology (ASCO), taking place May 30 to June 3 in Chicago. NSCLC, which accounts for 80% of lung cancer, is the most common cause of cancer death worldwide. Epidermal growth factor receptor (EGFR)-activating mutations (Del19 or L858R) are major oncogenic drivers of NSCLC. EGFR-positive NSCLC accounts for approximately 30% of all diagnosed cases of NSCLC (a similar market size to PD-L1-positive NSCLC, which is addressed by the world’s top-selling drug, Keytruda®). The current standard of care for EGFR-positive NSCLC is comprised of 3rd-generation inhibitors, most notably Osimertinib (Tagrisso®), whose annual sales exceed $6 billion. Most patients treated by tyrosine kinase inhibitors (TKIs) will eventually develop

NielsenIQ's Chief Technology Officer Mohit Kapoor Named Executive of the Year at Global Tech & AI Awards for Leading NIQ’s AI-Driven Tech Transformation20.5.2025 22:24:00 EEST | Press release

NielsenIQ (NIQ) is proud to announce that Mohit Kapoor, Chief Technology Officer, was named Executive of the Year at the inaugural Global Tech & AI Awards. This honor recognizes Mohit's exceptional leadership and visionary contributions to the tech industry, particularly in the realm of AI-powered consumer intelligence. "I am deeply honored to receive the Executive of the Year award at the Global Tech & AI Awards. This recognition is a testament to the incredible work and dedication of the entire NielsenIQ team,” said Mohit Kapoor, Chief Technology Officer, NIQ. “Together, we have redefined consumer and retail intelligence, leveraging AI to deliver unparalleled insights and drive meaningful change in the industry." Under Mohit's leadership, NIQ has adopted an AI-powered approach to its ambitious digital transformation which included a $400 million technology investment and the migration of its global client base onto Discover– a unified, cloud-based platform that seamlessly integrates

Strategic Partnership Between the Government of Morocco and TAQA Morocco, Nareva, ONEE and the Mohammed VI Investment Fund to Develop Key Power and Water Infrastructures in the Kingdom of Morocco20.5.2025 22:08:00 EEST | Press release

As part of the implementation of the commitments made in the joint declaration between His Majesty King Mohammed VI, may God Assist Him, and His Highness Sheikh Mohamed bin Zayed Al Nahyan, TAQA Morocco, in partnership with Nareva and the Mohammed VI Fund for Investment, has signed three memorandums of understanding and related development agreements with the Government of Morocco and ONEE. These agreements cover the development of structuring projects in the power, water and renewable energy sectors. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250520313620/en/ Strategic Partnership Between the Government of Morocco and TAQA Morocco, Nareva, ONEE and the Mohammed VI Investment Fund to Develop Key Power and Water Infrastructures in the Kingdom of Morocco (Photo: AETOSWire) The program aims to strengthen the Kingdom's water and energy sovereignty through the development of flexible natural gas-based power generation capacit

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye